English تحدث معنا →
الرئيسية / السياسات / إفصاحات الأمان
إفصاحات الأمان

إفصاحات الأمان.

وضعنا الأمني بلغة واضحة: الضوابط والشهادات والمعالجون الفرعيون وكيفية الإبلاغ عن ثغرة.

سارية منذ · 1 May 2026 الإصدار · 3.2 تنطبق على · lenscorp.ai وجميع منتجات LENS اللغات · العربية (ملخص) · الإنجليزية (النسخة المعتمدة)
ملاحظة عن الترجمة

ملخصات السياسات وعناصر التنقل والبيانات الوصفية مترجمة. أما النص القانوني الكامل أدناه فيعود إلى النص الإنجليزي المعتمد ما لم تكن هناك ترجمة معتمدة خاصة بالولاية القضائية.

01Security posture

LENS builds and operates AI products for cities, enterprises and critical infrastructure. We treat security as a precondition for that work, not a feature. Our posture is published, our claims are auditable, and our controls are designed for customer review.

02Certifications & audits

StandardStatusLast assessment
ISO/IEC 27001:2022Certified · BSIFeb 2026
ISO/IEC 27701:2019 (PIMS)Certified · BSIFeb 2026
SOC 2 Type IIReported · Big FourMar 2026 (12-month period)
NIST CSF 2.0Self-assessed Tier 3Apr 2026
HIPAA Security RuleAligned (BAA-ready)Continuous

Reports under NDA: trust@lenscorp.ai.

03Selected controls

Encryption

TLS 1.2+ in transit (TLS 1.3 preferred). AES-256 at rest using FIPS 140-2 validated modules. Key custody via AWS KMS / Azure Key Vault with annual rotation.

Access

SSO with hardware MFA for production. JIT elevation with reviewer approval. Quarterly access reviews. No standing root access.

Logging

Immutable audit logs for every production action. 1-year hot retention; 6-year cold retention for PHI/regulated workloads.

Network

Zero-trust internal model — every service-to-service call is mutually authenticated. Public ingress only via Cloudflare with WAF + bot management.

SDLC

Required code review by a second engineer. SAST (Semgrep) and SCA (Snyk) on every PR. Dependency upgrade SLA: 7 days for high, 30 days for medium.

Incident response

24×7 on-call. Page-tested every quarter. Customer notification within 72 hours of confirmed incident; 5 business days for HIPAA Breach.

04Vulnerability disclosure

Found something? We want to hear from you. We commit to:

  • Acknowledging your report within 2 business days.
  • Triaging within 5 business days.
  • Not pursuing legal action against good-faith researchers operating under this policy.

Scope

In scope: *.lenscorp.ai, the LENS-operated demo endpoints listed at /security.txt, and our published mobile apps. Out of scope: customer-operated deployments (contact the customer), social engineering, physical attacks, denial of service.

How to report

PGP-encrypted email to security@lenscorp.ai (key fingerprint: 4F2A 8C19 6E3D 7B91 5C42 A0E8 3F27 9D14 6B8E 5A3F). Or via our HackerOne private programme — request an invite at the same address.

05Bug bounty

We pay for valid, novel reports on a sliding scale: USD 100–250 (low), 250–1,000 (medium), 1,000–5,000 (high), 5,000–15,000 (critical). Duplicates and out-of-scope reports are not eligible.

06Contact

هل تحتاج إشعاراً خاصاً بمنطقتك؟

ننشر إشعارات تكميلية للهند والاتحاد الأوروبي/المملكة المتحدة وقطاع الصحة الأمريكي وكاليفورنيا والبرازيل.

عرض جميع السياسات